Why this page exists

Buyers, CISOs, and journalists often treat every “security organisation in Hong Kong” as interchangeable. That creates two problems: people contact the wrong channel during an incident, and they misread Trust Reviews as if they were government clearances.

This page explains the difference in plain language — and how to use both correctly for Hong Kong cybersecurity and AI security work.

Short answer

HKCERT (Hong Kong Computer Emergency Response Team Coordination Centre) is Hong Kong’s public Computer Emergency Response Team. It is the coordination point people should use for incident response, official advisories, and national cyber hygiene programmes.

HKISG (Hong Kong Information Security Group) is an independent membership organisation. We publish education, security news, methodology-based Trust Reviews, security bulletins, and practitioner materials spanning classical cyber controls and AI security. We are not a government department, regulator, or national CERT.

If you remember only one rule: HKCERT for national incident coordination; HKISG for inspectable trust signals, education, and programme methodology.

Side-by-side comparison

Dimension
HKCERT
HKISG
Primary role
National CERT coordination and public advisories
Independent membership programmes and trust signals
Best for
Active incidents, official guidance, national hygiene campaigns
Bulletins with programme context, Trust Reviews, AI security education, board packs
Authority type
Public CERT function
Private membership organisation with published methodology
Scores / stars
Does not issue HKISG TrustScores
Publishes dated Trust Reviews under Methodology v2026.2
AI security
May publish advisories relevant to AI-enabled threats
Scores AI posture (inventory, abuse testing, oversight) inside Trust Reviews
Membership
Not an HKISG membership scheme
Annual membership funds capacity — not scores

When to use which

Use this decision path before you escalate:

  1. Systems are actively compromised, ransomware is spreading, or you need national CERT help → go to HKCERT first.
  2. You need an early-warning note with HKISG risk labels and operator cuesSecurity Bulletins.
  3. You need a dated public trust profile (including AI lenses and website hygiene)Trust Reviews and Methodology.
  4. The board asks “what should we learn about AI risk?”Online Education, AI Security wiki, and Prompt Injection.
  5. The question is personal data / PDPO / automated decisionsPCPD for regulatory guidance, plus HKISG’s privacy wiki and PDPO news context.

Typical Hong Kong scenarios

Scenario A — Edge appliance zero-day
Patch and contain using vendor + HKCERT guidance. Use HKISG bulletins/news for board language and evidence capture if you later enter a Trust Review.

Scenario B — AI chatbot may have leaked customer data
Treat it as both an incident (HKCERT / legal / PCPD pathways as applicable) and an AI security control failure (inventory, prompt/tool abuse, human oversight). HKISG methodology domains describe the control language; they do not replace CERT response.

Scenario C — Vendor claims “CERT-approved” because of an HKISG star
That claim is wrong. TrustScores are independent programme outcomes, not CERT clearances. Ask for scope, date, methodology version, and limitations on the public review page.

How HKISG references HKCERT

HKISG articles and bulletins often point readers to HKCERT when national coordination or official advisories apply. Citing HKCERT does not mean HKISG speaks for HKCERT, and it does not create a joint certification.

If an HKISG page and an HKCERT advisory conflict on urgency or technical remediation, follow the CERT advisory for incident response. Then use HKISG materials for:

  • board and risk-committee framing
  • Trust Review evidence packs
  • AI security literacy and methodology alignment
  • education pathways for teams

AI security: what each organisation does — and does not do

Neither HKCERT nor HKISG “certifies” that an AI product is permanently safe.

HKISG’s Methodology v2026.2 treats AI security as a first-class domain: model/GenAI inventory, abuse testing (including prompt injection), data integrity, human oversight, third-party LLM risk, and AI-assisted defence discipline. Product-level white-hat recognition, when applicable, sits under IT Awards.

HKCERT remains the coordination reference when AI-enabled attacks become active incidents (for example large-scale deepfake fraud campaigns or exploited AI features in widely used platforms).

Common misconceptions

  • “HKISG is a government body.” No. Independent membership organisation.
  • “A 5.0 TrustScore means HKCERT cleared the vendor.” No. Different programmes entirely.
  • “If HKCERT published an advisory, I do not need HKISG.” You may still need education, Trust Reviews, or board materials — different job.
  • “Membership buys stars.” No. Fees fund capacity; scores follow published rules under Governance.

Hong Kong operator checklist

  1. Bookmark HKCERT for incident and advisory channels; test that your on-call team knows the path.
  2. Subscribe to HKISG Security News and Bulletins for operator context between major advisories.
  3. Never treat TrustScores as CERT clearances in RFPs or press quotes.
  4. Keep a dated evidence pack (tickets, patch timestamps, AI inventory notes) whenever you act on either source.
  5. For AI systems, maintain owners, abuse-test notes, and human-confirmation gates — see Prompt Injection.
  6. Separate privacy questions (PCPD / PDPO) from CERT response and from Trust Review scoring.

Editorial note

Published by the Hong Kong Information Security Group for educational clarity. Always verify current HKCERT guidance on hkcert.org. This page is not legal advice, not a regulatory opinion, and not a substitute for national CERT coordination.